Authority
Who can create, delegate, and revoke authority?
Use architecture, threat models, deployment boundaries, and evidence requirements to evaluate controls without invented benchmarks or customer claims.
Who can create, delegate, and revoke authority?
Where is a decision checked before action executes?
Does every unavailable or ambiguous control fail closed?
Can reviewers connect intent, decision, approval, and outcome?
Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.
Document the environment, threat model, and integration boundary.
Select protocols, signals, policies, and failure behavior.
Test vendor-specific APIs, tenant isolation, and abuse paths.
Mark available only after deployed end-to-end verification.